LWN.net Logo

hplip: symlink attack

Package(s):hplip CVE #(s):CVE-2011-2722
Created:September 12, 2011 Updated:February 21, 2013
Description: From the Red Hat bugzilla:

A temporary file handling flaw was reported in prnt/hpijs/hpcupsfax.cpp, the hplip HP CUPS filter. Because a predictable temporary filename is used (/tmp/hpcupsfax.out), an attacker could use a symlink attack to overwrite an arbitrary file with the privileges of the process running the HP CUPS fax filter.

Alerts:
Fedora FEDORA-2011-11189 2011-08-19
Fedora FEDORA-2011-11199 2011-08-19
Gentoo 201203-17 2012-03-16
Oracle ELSA-2013-0133 2013-01-12
Scientific Linux SL-hpli-20130116 2013-01-16
CentOS CESA-2013:0133 2013-01-09
Red Hat RHSA-2013:0500-02 2013-02-21
Oracle ELSA-2013-0500 2013-02-28
Scientific Linux SL-hpli-20130304 2013-03-04
CentOS CESA-2013:0500 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds